ISC2 CC Security Operations Practice Question
An organization wants to ensure that only authorized devices can connect to its corporate Wi-Fi network. The security team decides to implement a solution that requires devices to authenticate before being granted network access. Which technology should they use?
⚠ Common exam trap
Many candidates confuse WPA3-SAE, which is a strong encryption protocol, with network access control; it still uses a shared password and does not authenticate individual devices.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
802.1X with a RADIUS server
802.1X with a RADIUS server provides port-based network access control, requiring each device to authenticate before being granted access. It supports various authentication methods such as certificates or credentials, making it ideal for ensuring only authorized devices connect to corporate Wi-Fi. Other options like pre-shared keys or MAC filtering are weaker and not scalable for enterprise use.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
MAC address filtering
Why it's wrong here
MAC address filtering allows or denies devices based on their hardware address, but MAC addresses can be spoofed easily. It does not provide strong authentication and is difficult to manage in large environments. It is not a robust solution for ensuring only authorized devices connect.
- ✗
WPA3-SAE with a shared password
Why it's wrong here
WPA3-SAE improves security over WPA2-Personal by using Simultaneous Authentication of Equals, but it still relies on a shared password. It does not provide individual device authentication or integration with directory services. For corporate environments needing per-device authorization, 802.1X is more suitable.
- ✗
WPA2-Personal with a pre-shared key
Why it's wrong here
WPA2-Personal uses a pre-shared key that is shared among all users. It does not provide per-device authentication or prevent unauthorized devices if the key is known. It is suitable for home networks but lacks the granular access control needed for corporate environments where only authorized devices should connect.
- ✓
802.1X with a RADIUS server
Why this is correct
802.1X is an IEEE standard for port-based network access control that requires devices to authenticate via a RADIUS server before gaining network access. It supports per-device credentials, certificates, or other methods, ensuring only authorized devices connect. This is the appropriate solution for corporate Wi-Fi networks requiring strong authentication.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
Learn chapter
Network Security Components and Controls
Key term
Authentication
Authentication is the process of verifying that someone or something is who or what it claims to be before granting access to a system or resource.
Key term
Remote Authentication Dial-in User Service
RADIUS is a network protocol that provides centralized authentication, authorization, and accounting for users trying to connect to a network service.
About these practice questions
This CC question is part of Courseiva's 989-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.